CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

OceanLotus (APT32) Threat Actor Profile

June 25, 2026

OceanLotus, also known as APT32, is a Vietnam-aligned advanced persistent threat group active since 2012. It has historically targeted foreign entities, including China, but has recently shifted focus to domestic espionage in Vietnam. The group uses sophisticated tooling like SPECTRALVIPER and has been linked to supply chain attacks.